VYPR

CVEs

37,997 total · page 597 of 760

  • CVE-2019-19334CriDec 6, 2019
    risk 0.57cvss 9.8epss 0.04

    In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "identityref". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, which would allow an…

  • CVE-2019-19333CriDec 6, 2019
    risk 0.57cvss 9.8epss 0.04

    In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, which would allow an attacker to…

  • CVE-2019-19617CriDec 6, 2019
    risk 0.57cvss 9.8epss 0.03

    phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php and libraries/classes/Footer.php.

  • CVE-2019-7195CriKEVDec 5, 2019
    risk 0.92cvss 9.8epss 0.90

    This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

  • CVE-2019-7194CriKEVDec 5, 2019
    risk 0.91cvss 9.8epss 0.83

    This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.

  • CVE-2019-7193CriKEVDec 5, 2019
    risk 0.83cvss 9.8epss 0.14

    This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

  • CVE-2019-7192CriKEVDec 5, 2019
    risk 0.92cvss 9.8epss 0.88

    This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.

  • CVE-2019-7183CriDec 5, 2019
    risk 0.64cvss 9.8epss 0.02

    This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, QNAP recommend updating QTS to their latest versions.

  • CVE-2019-19595CriDec 5, 2019
    risk 0.64cvss 9.8epss 0.04

    reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for PrestaShop allows remote attackers to execute arbitrary code by uploading a .php file.

  • CVE-2019-19594CriDec 5, 2019
    risk 0.64cvss 9.8epss 0.04

    reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allows remote attackers to execute arbitrary code by uploading a .php file.

  • CVE-2019-15897CriDec 5, 2019
    risk 0.63cvss 9.6epss 0.03

    beegfs-ctl in ThinkParQ BeeGFS through 7.1.3 allows Authentication Bypass via communication with a BeeGFS metadata server (which is typically not exposed to external networks).

  • CVE-2019-14910CriDec 5, 2019
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has entered.

  • CVE-2019-19317CriDec 5, 2019
    risk 0.57cvss 9.8epss 0.04

    lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have unspecified other impact.

  • CVE-2019-19589CriDec 5, 2019
    risk 0.64cvss 9.8epss 0.02

    The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid JAR archives. Note: It has been argued that "The vulnerability reported in PDF Embedder Plugin is not valid as the plugin itself doesn't control or manage the…

  • CVE-2019-19521CriDec 5, 2019
    risk 0.64cvss 9.8epss 0.03

    libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/auth_subr.c and gen/authenticate.c in libc (and login/login.c and xenocara/app/xenodm/greeter/verify.c).

  • CVE-2013-2745CriDec 4, 2019
    risk 0.64cvss 9.8epss 0.02

    An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0

  • CVE-2019-19228CriDec 4, 2019
    risk 0.64cvss 9.8epss 0.02

    Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.

  • CVE-2019-19576CriDec 4, 2019
    risk 0.62cvss 9.8epss 0.26

    class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! and other products, omits .phar from the set of dangerous file extensions.

  • CVE-2019-17556CriDec 4, 2019
    risk 0.64cvss 9.8epss 0.04

    Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized. If an attacker can feed malicious metadata to the class, then it may result in running attacker's code in the worse…

  • CVE-2019-11940CriDec 4, 2019
    risk 0.64cvss 9.8epss 0.01

    In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table into a corrupted state, leading to a use-after-free condition and undefined behavior. This issue affects Proxygen from v0.29.0…

  • CVE-2019-11936CriDec 4, 2019
    risk 0.64cvss 9.8epss 0.01

    Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0,…

  • CVE-2019-11935CriDec 4, 2019
    risk 0.64cvss 9.8epss 0.01

    Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0,…

  • CVE-2019-11934CriDec 4, 2019
    risk 0.64cvss 9.8epss 0.02

    Improper handling of close_notify alerts can result in an out-of-bounds read in AsyncSSLSocket. This issue affects folly prior to v2019.11.04.00.

  • CVE-2019-11930CriDec 4, 2019
    risk 0.64cvss 9.8epss 0.03

    An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0,…

  • CVE-2018-0730CriDec 4, 2019
    risk 0.64cvss 9.8epss 0.02

    This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.

  • CVE-2018-0729CriDec 4, 2019
    risk 0.64cvss 9.8epss 0.02

    This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions.

  • CVE-2019-5096CriDec 3, 2019
    risk 0.69cvss 9.8epss 0.67

    An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A specially crafted HTTP request can lead to a use-after-free condition during the…

  • CVE-2019-19459CriDec 3, 2019
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary…

  • CVE-2019-16885CriDec 3, 2019
    risk 0.64cvss 9.8epss 0.05

    In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. This could happen at two places: first in view/ProductsView.php using the cookie price_filter, and second in api/Comparison.php via…

  • CVE-2013-4486CriDec 3, 2019
    risk 0.57cvss 9.8epss 0.01

    Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging

  • CVE-2019-19021CriDec 2, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privileges. Anybody can log in with this account.

  • CVE-2019-19015CriDec 2, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in TitanHQ WebTitan before 5.18. The proxy service (which is typically exposed to all users) allows connections to the internal PostgreSQL database of the appliance. By connecting to the database through the proxy (without password authentication), an…

  • CVE-2019-12518CriDec 2, 2019
    risk 0.71cvss 9.8epss 0.51

    Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.

  • CVE-2019-12503CriDec 2, 2019
    risk 0.64cvss 9.8epss 0.02

    Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keystroke injection attacks. Thus, an attacker is able to send arbitrary keystrokes to a victim's computer system, e.g., to install malware when the target system…

  • CVE-2019-12394CriDec 2, 2019
    risk 0.64cvss 9.8epss 0.02

    Anviz access control devices allow unverified password change which allows remote attackers to change the administrator password without prior authentication.

  • CVE-2019-12392CriDec 2, 2019
    risk 0.64cvss 9.8epss 0.02

    Anviz access control devices allow remote attackers to issue commands without a password.

  • CVE-2019-19502CriDec 2, 2019
    risk 0.64cvss 9.8epss 0.02

    Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.

  • CVE-2019-19245CriDec 2, 2019
    risk 0.67cvss 9.8epss 0.08

    NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used.

  • CVE-2019-19492CriDec 2, 2019
    risk 0.69cvss 9.8epss 0.29

    FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.

  • CVE-2019-15631CriDec 2, 2019
    risk 0.64cvss 9.8epss 0.02

    Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.

  • CVE-2019-18609CriDec 1, 2019
    risk 0.57cvss 9.8epss 0.03

    An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller…

  • CVE-2019-19391CriNov 29, 2019
    risk 0.59cvss 9.1epss 0.01

    In LuaJIT through 2.0.5, as used in Moonjit before 2.1.2 and other products, debug.getinfo has a type confusion issue that leads to arbitrary memory write or read operations, because certain cases involving valid stack levels and > options are mishandled. NOTE: The LuaJIT…

  • CVE-2019-14901CriNov 29, 2019
    risk 0.65cvss 9.8epss 0.16

    A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability allows a remote attacker to cause a system crash, resulting in a denial of service, or execute arbitrary code. The highest threat with…

  • CVE-2019-14897CriNov 29, 2019
    risk 0.64cvss 9.8epss 0.03

    A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a STA works in IBSS mode (allows connecting stations…

  • CVE-2019-14895CriNov 29, 2019
    risk 0.64cvss 9.8epss 0.08

    A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote devices country settings. This…

  • CVE-2019-18253CriNov 27, 2019
    risk 0.65cvss 10.0epss 0.02

    An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (versions 1p1r26, 1.2.3.17, 2.0.0.10, RES670 2.0.0.4, 2.1.0.1, and prior) outside the intended directory.

  • CVE-2019-6665CriNov 27, 2019
    risk 0.61cvss 9.4epss 0.01

    On BIG-IP ASM 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, BIG-IQ 6.0.0 and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, an attacker with access to the device communication between the BIG-IP ASM Central Policy Builder and the…

  • CVE-2011-2717CriNov 27, 2019
    risk 0.64cvss 9.8epss 0.04

    The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.

  • CVE-2011-2523CriNov 27, 2019
    risk 0.74cvss 9.8epss 0.96

    vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.

  • CVE-2019-19330CriNov 27, 2019
    risk 0.64cvss 9.8epss 0.04

    The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.